{"record":{"id":"0d1b8be3e6b8911b","repo":"kubernetes/kops","slug":"incorrect-token-format","errorCode":null,"errorMessage":"incorrect token format","messagePattern":"incorrect token format","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"upup/pkg/fi/cloudup/azure/verifier.go","lineNumber":112,"sourceCode":"\tcase vmssVMResourceType:\n\t\treturn res.Parent.Name + \"/\" + res.Name\n\tdefault:\n\t\treturn res.ResourceType.String() + \"/\" + res.Name\n\t}\n}\n\n// VerifyToken validates the Azure attestation token, confirms the claimed VM through the Azure API,\n// and returns the node bootstrap identity.\nfunc (a azureVerifier) VerifyToken(ctx context.Context, rawRequest *http.Request, token string, body []byte) (*bootstrap.VerifyResult, error) {\n\tif !strings.HasPrefix(token, azuremetadata.AzureAuthenticationTokenPrefix) {\n\t\treturn nil, bootstrap.ErrNotThisVerifier\n\t}\n\n\t// Token format: \"x-azure-id <resourceID> <base64-pkcs7-signature>\"\n\ttokenPayload := strings.TrimPrefix(token, azuremetadata.AzureAuthenticationTokenPrefix)\n\tresourceID, signature, ok := strings.Cut(tokenPayload, \" \")\n\tif !ok || resourceID == \"\" || signature == \"\" {\n\t\treturn nil, fmt.Errorf(\"incorrect token format\")\n\t}\n\n\t// Parse the resource ID early to reject malformed tokens before expensive crypto.\n\tres, err := arm.ParseResourceID(resourceID)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"parsing resource ID: %w\", err)\n\t}\n\tvmLogID := vmLogIDFromResource(res)\n\tresourceType := res.ResourceType.String()\n\tklog.V(4).Infof(\"Azure verifier for VM %q parsed resource ID: subscription=%q resourceGroup=%q\", vmLogID, res.SubscriptionID, res.ResourceGroupName)\n\n\t// Reject resource IDs outside the verifier's own subscription / resource group. The Azure API lookup below\n\t// is already scoped to kops-controller's subscription and resource group, so any claim that names a different\n\t// location cannot describe a cluster VM. Failing here avoids a wasted Azure API call and makes the scope\n\t// explicit instead of implicit.\n\tif !strings.EqualFold(res.SubscriptionID, a.client.subscriptionID) {\n\t\treturn nil, fmt.Errorf(\"resource ID subscription %q does not match verifier subscription %q\", res.SubscriptionID, a.client.subscriptionID)\n\t}","sourceCodeStart":94,"sourceCodeEnd":130,"githubUrl":"https://github.com/kubernetes/kops/blob/4c8573c808a73d578c5eadc86d410646ea0b0d73/upup/pkg/fi/cloudup/azure/verifier.go#L94-L130","documentation":"Guard in VerifyToken: the token carries the Azure prefix but does not split into the expected 'x-azure-id <resourceID> <base64-signature>' three-part form, so the resource ID and signature cannot be extracted.","triggerScenarios":"Thrown at upup/pkg/fi/cloudup/azure/verifier.go:112 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Reject the bootstrap token","Regenerate the token on the node so the full three-part format is produced","Check for proxies or middleware truncating the Authorization header"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"4c8573c808a73d578c5eadc86d410646ea0b0d73","analyzedAt":"2026-09-05T04:13:19.212Z","contentChangedAt":"2026-09-05T04:13:19.212Z","schemaVersion":2},"datasetVersion":"2026-09-12T07:17:12.445Z"}